ID

VAR-201904-1334


CVE

CVE-2018-4462


TITLE

plural Apple Updates to product vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2018-010217

DESCRIPTION

A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.2. Apple Has released an update for each product.The expected impact depends on each vulnerability, but can be affected as follows: * Privilege escalation * Access restriction avoidance * Arbitrary code execution * Service operation interruption (DoS) * information leak * Incorrect configuration profile usage * UI Spoofing * Address bar impersonation. This vulnerability allows local attackers to disclose sensitive information on vulnerable installations of Apple macOS. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.The specific flaw exists within the handling of the getPixelInformationFromTiming method. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before reading from memory. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges in the context of the kernel. Apple macOS Mojave is a set of dedicated operating systems developed by Apple for Mac computers. AMD is one of the components used in AMD products. The vulnerability stems from the failure of the network system or product to properly validate the input data. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2018-12-05-2 macOS Mojave 10.14.2, Security Update 2018-003 High Sierra, Security Update 2018-006 Sierra macOS Mojave 10.14.2, Security Update 2018-003 High Sierra, Security Update 2018-006 Sierra are now available and addresses the following: Airport Available for: macOS Mojave 10.14.1 Impact: A malicious application may be able to elevate privileges Description: A type confusion issue was addressed with improved memory handling. CVE-2018-4303: Mohamed Ghannam (@_simo36) AMD Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14.1 Impact: An application may be able to read restricted memory Description: A validation issue was addressed with improved input sanitization. CVE-2018-4462: Lilang Wu and Moony Li of TrendMicro Mobile Security Research Team Carbon Core Available for: macOS Mojave 10.14.1 Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2018-4463: Maksymilian Arciemowicz (cxsecurity.com) Disk Images Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14.1 Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2018-4465: Pangu Team Intel Graphics Driver Available for: macOS Mojave 10.14.1 Impact: A local user may be able to cause unexpected system termination or read kernel memory Description: An out-of-bounds read was addressed with improved input validation. CVE-2018-4434: Zhuo Liang of Qihoo 360 Nirvan Team IOHIDFamily Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6 Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2018-4427: Pangu Team Kernel Available for: macOS Mojave 10.14.1 Impact: An attacker in a privileged position may be able to perform a denial of service attack Description: A denial of service issue was addressed by removing the vulnerable code. CVE-2018-4460: Kevin Backhouse of Semmle Security Research Team Kernel Available for: macOS High Sierra 10.13.6, macOS Mojave 10.14.1 Impact: A local user may be able to read kernel memory Description: A memory initialization issue was addressed with improved memory handling. CVE-2018-4431: An independent security researcher has reported this vulnerability to Beyond Security's SecuriTeam Secure Disclosure program Kernel Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14.1 Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved state management. CVE-2018-4447: Juwei Lin(@panicaII) and Zhengyu Dong of TrendMicro Mobile Security Team Kernel Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14.1 Impact: A malicious application may be able to elevate privileges Description: A logic issue was addressed with improved restrictions. CVE-2018-4435: Jann Horn of Google Project Zero, Juwei Lin(@panicaII) and Junzhi Lu of TrendMicro Mobile Security Team Kernel Available for: macOS Mojave 10.14.1 Impact: An application may be able to execute arbitrary code with kernel privileges Description: A memory corruption issue was addressed with improved input validation. CVE-2018-4461: Ian Beer of Google Project Zero WindowServer Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14.1 Impact: An application may be able to execute arbitrary code with system privileges Description: A memory corruption issue was addressed with improved memory handling. CVE-2018-4449: Hanqing Zhao, Yufeng Ruan and Kun Yang of Chaitin Security Research Lab CVE-2018-4450: Hanqing Zhao, Yufeng Ruan and Kun Yang of Chaitin Security Research Lab Additional recognition LibreSSL We would like to acknowledge Keegan Ryan of NCC Group for their assistance. NetAuth We would like to acknowledge Vladimir Ivanov of Digital Security for their assistance. Simple certificate enrollment protocol (SCEP) We would like to acknowledge Tim Cappalli of Aruba and a Hewlett Packard Enterprise company for their assistance. Installation note: macOS Mojave 10.14.2, Security Update 2018-003 High Sierra, Security Update 2018-006 Sierra may be obtained from the Mac App Store or Apple's Software Downloads web site: https://support.apple.com/downloads/ Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQJdBAEBCABHFiEEDNXJVNCJJEAVmJdZeC9tht7TK3EFAlwINzopHHByb2R1Y3Qt c2VjdXJpdHktbm9yZXBseUBsaXN0cy5hcHBsZS5jb20ACgkQeC9tht7TK3FxTw// fUx30FH3eQXRRc/dlM5LgBdDqx/TOHtSwjiTLkVRHC1czz9ledAmHmGkg00z6b+p 5LsZNaZRUF3FVxuWUcm0rQQ+MpSj+BpCDZX0X+pXHX+QvNjad8ZcQsIqjtnJ1omZ jr2eUQtnkmbnaFX+TiesIN8tGBQ2Gve1/fqzrXdpqlF6j9U76gw4djI4JbAnLGxH IzjIp1FukQy1phfZZcHd++aEHvsQeJ0bT0INajqtNOkDQSZ0H7/NIW1BoUQlcpLG cqz+dwTYFwfqvNUmQ5PUTFXQJHxiVBRgMDdyesrVSKSuvEqTNAQKCOXMxayVbotf LBlghqpPr2XTS7enRkY87BU+aSdTTzjTX7fvQBOQgAJPb7L3FXhA/dCTHWV3RyWY 1qrTFOIvbfAtCjsBIqHC0nD5GWXB7vuxPvcYQXlNYl/MxMv3vAANHi8aI+YJ8Usp 6qLLD02Z4H4E8ZpmakqqFJT6ORGUIBpvqG9rYxhACTe/z2uqZ7scD4I4crpfPIIk WRyh17q87z+dTCIS4P9PbYdrx7Y8SHN8K9uaBmZVq9WqaAVtCet9S0zNBrLai2Sj ar3y5Sgso7RMI5KhB0IGNyS2LZL0a3ypQVfVEWpxoRjIHyI2sJSPAuXOLrwV6pRU +61jWoLyn0cbMWMEhfrw/ulTOcMBjIXV7EHZNge8H5Ex+L -----END PGP SIGNATURE-----

Trust: 3.15

sources: NVD: CVE-2018-4462 // JVNDB: JVNDB-2018-010217 // JVNDB: JVNDB-2018-014853 // ZDI: ZDI-18-1364 // VULHUB: VHN-134493 // PACKETSTORM: 150669

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:ltversion:10.14.2

Trust: 1.0

vendor:applemodel:icloudscope:ltversion:for windows 7.9 earlier

Trust: 0.8

vendor:applemodel:iosscope:ltversion:12.1.1 earlier

Trust: 0.8

vendor:applemodel:itunesscope:ltversion:12.9.2 for windows earlier

Trust: 0.8

vendor:applemodel:macos high sierrascope:eqversion:(security update 2018-003 not applied )

Trust: 0.8

vendor:applemodel:macos mojavescope:ltversion:10.14.2 earlier

Trust: 0.8

vendor:applemodel:macos sierrascope:eqversion:(security update 2018-006 not applied )

Trust: 0.8

vendor:applemodel:safariscope:ltversion:12.0.2 earlier

Trust: 0.8

vendor:applemodel:tvosscope:ltversion:12.1.1 earlier

Trust: 0.8

vendor:applemodel:watchosscope:ltversion:5.1.2 earlier

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.12.6

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.13.6

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.14.1

Trust: 0.8

vendor:applemodel:os xscope: - version: -

Trust: 0.7

sources: ZDI: ZDI-18-1364 // JVNDB: JVNDB-2018-010217 // JVNDB: JVNDB-2018-014853 // NVD: CVE-2018-4462

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-4462
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-4462
value: MEDIUM

Trust: 0.8

ZDI: CVE-2018-4462
value: MEDIUM

Trust: 0.7

CNNVD: CNNVD-201812-225
value: MEDIUM

Trust: 0.6

VULHUB: VHN-134493
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-4462
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-134493
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-4462
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.0

Trust: 1.8

ZDI: CVE-2018-4462
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-18-1364 // VULHUB: VHN-134493 // JVNDB: JVNDB-2018-014853 // CNNVD: CNNVD-201812-225 // NVD: CVE-2018-4462

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-134493 // JVNDB: JVNDB-2018-014853 // NVD: CVE-2018-4462

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201812-225

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-201812-225

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-010217

PATCH

title:About the security content of macOS Mojave 10.14.2, Security Update 2018-003 High Sierra, Security Update 2018-006 Sierraurl:https://support.apple.com/en-us/HT209341

Trust: 2.3

title:About the security content of tvOS 12.1.1url:https://support.apple.com/en-us/HT209342

Trust: 0.8

title:About the security content of watchOS 5.1.2url:https://support.apple.com/ja-jp/HT209343

Trust: 0.8

title:About the security content of Safari 12.0.2url:https://support.apple.com/en-us/HT209344

Trust: 0.8

title:About the security content of iCloud for Windows 7.9url:https://support.apple.com/en-us/HT209346

Trust: 0.8

title:About the security content of iOS 12.1.1url:https://support.apple.com/en-us/HT209340

Trust: 0.8

title:About the security content of iTunes 12.9.2 for Windowsurl:https://support.apple.com/en-us/HT209345

Trust: 0.8

title:HT209341url:https://support.apple.com/ja-jp/HT209341

Trust: 0.8

title:Apple macOS AMD Security hole Repair measuresurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=87506

Trust: 0.6

sources: ZDI: ZDI-18-1364 // JVNDB: JVNDB-2018-010217 // JVNDB: JVNDB-2018-014853 // CNNVD: CNNVD-201812-225

EXTERNAL IDS

db:NVDid:CVE-2018-4462

Trust: 3.3

db:JVNid:JVNVU92431031

Trust: 1.6

db:JVNDBid:JVNDB-2018-010217

Trust: 0.8

db:JVNDBid:JVNDB-2018-014853

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-7302

Trust: 0.7

db:ZDIid:ZDI-18-1364

Trust: 0.7

db:CNNVDid:CNNVD-201812-225

Trust: 0.7

db:VULHUBid:VHN-134493

Trust: 0.1

db:PACKETSTORMid:150669

Trust: 0.1

sources: ZDI: ZDI-18-1364 // VULHUB: VHN-134493 // JVNDB: JVNDB-2018-010217 // JVNDB: JVNDB-2018-014853 // PACKETSTORM: 150669 // CNNVD: CNNVD-201812-225 // NVD: CVE-2018-4462

REFERENCES

url:https://support.apple.com/kb/ht209341

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-4462

Trust: 1.5

url:https://jvn.jp/vu/jvnvu92431031/

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-4462

Trust: 0.8

url:https://jvn.jp/vu/jvnvu92431031/index.html

Trust: 0.8

url:https://support.apple.com/en-us/ht209341

Trust: 0.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-4447

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4303

Trust: 0.1

url:https://support.apple.com/kb/ht201222

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4431

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4465

Trust: 0.1

url:https://www.apple.com/support/security/pgp/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4450

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4427

Trust: 0.1

url:https://support.apple.com/downloads/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4460

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4463

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4449

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4434

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4435

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-4461

Trust: 0.1

sources: ZDI: ZDI-18-1364 // VULHUB: VHN-134493 // JVNDB: JVNDB-2018-010217 // JVNDB: JVNDB-2018-014853 // PACKETSTORM: 150669 // CNNVD: CNNVD-201812-225 // NVD: CVE-2018-4462

CREDITS

Lilang Wu, Moony Li of TrendMicro Mobile Security Research Team

Trust: 0.7

sources: ZDI: ZDI-18-1364

SOURCES

db:ZDIid:ZDI-18-1364
db:VULHUBid:VHN-134493
db:JVNDBid:JVNDB-2018-010217
db:JVNDBid:JVNDB-2018-014853
db:PACKETSTORMid:150669
db:CNNVDid:CNNVD-201812-225
db:NVDid:CVE-2018-4462

LAST UPDATE DATE

2024-11-23T20:37:54.281000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-18-1364date:2018-12-10T00:00:00
db:VULHUBid:VHN-134493date:2019-04-05T00:00:00
db:JVNDBid:JVNDB-2018-010217date:2018-12-10T00:00:00
db:JVNDBid:JVNDB-2018-014853date:2019-04-17T00:00:00
db:CNNVDid:CNNVD-201812-225date:2019-04-15T00:00:00
db:NVDid:CVE-2018-4462date:2024-11-21T04:07:26.697

SOURCES RELEASE DATE

db:ZDIid:ZDI-18-1364date:2018-12-10T00:00:00
db:VULHUBid:VHN-134493date:2019-04-03T00:00:00
db:JVNDBid:JVNDB-2018-010217date:2018-12-07T00:00:00
db:JVNDBid:JVNDB-2018-014853date:2019-04-17T00:00:00
db:PACKETSTORMid:150669date:2018-12-06T18:55:48
db:CNNVDid:CNNVD-201812-225date:2018-12-06T00:00:00
db:NVDid:CVE-2018-4462date:2019-04-03T18:29:17.190